ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

Hacked Thai College Domain Used for 'Zero-Code Cloaking' to Funnel Google Searchers to Illegal Casino Sites

mediumPhishing & fraudexploited in the wildimportance 45
What's new: First merged summary for this story — no previous report existed. Key developments introduced: disclosure of the zero-code cloaking technique abusing the hacked km.chpc.ac.th domain, the scale figures (30 million gambling URLs across ~1,000 Thai public-sector sites, 683 blocked Indonesian gov/edu sites, 15,000+ compromised domains for sale per Netcraft), and ADEX's recommendations that ad…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Anti-fraud platform ADEX documented a 'zero-code cloaking' scheme in which a casino page planted on the compromised Thai education domain km.chpc.ac.th was indexed by Google and ranked first for targeted queries, chaining a real Google search results page and…

ADEX researchers found a casino-themed page planted on the compromised km.chpc.ac.th domain in Thailand's educational .ac.th zone. Google indexed the page and ranked it first for targeted queries, so an ad's destination URL could simply load a genuine Google search results page whose poisoned top result was the hacked page, which then redirected visitors to illegal online gambling sites. Because every visitor received identical content and no cloaking code was deployed, ad-verification tools that inspect only the declared landing URL detected nothing malicious. ADEX frames the technique as part of a global 'domain-borrowing' campaign against government and education sites: Thailand reports roughly 30 million gambling URLs across about 1,000 public-sector sites, Indonesia has blocked 683 government and education sites, and Netcraft tracks an underground market selling access to more than 15,000 compromised domains (described by Netcraft per ADEX as .gov, .edu and ccTLD domains; GBHackers characterized the same 15,000+ figure as gov/edu domains). ADEX argues Google's site reputation abuse policy offers little coverage because hijacked institutions are victims rather than willing participants, and it urges ad networks to treat .ac., .gov and .edu zones as flags in redirect chains. The findings were reported on 2026-09-17.

  • ADEX found a casino-themed page planted on the compromised km.chpc.ac.th domain in Thailand's .ac.th educational zone.
  • Google indexed and ranked the planted casino page first for targeted queries, enabling it to act as the redirect hop.
  • The 'zero-code cloaking' technique chains a genuine Google search results page and a third-party redirect; no custom cloaking code was deployed.
  • Every visitor received identical content, so ad-verification tools that inspect only the declared landing URL detected nothing malicious.
  • Thailand reports roughly 30 million gambling URLs across about 1,000 public-sector sites.
  • Indonesia blocked 683 government and education sites (Report 2 cites the same figure as 'hundreds' of blocked gov/edu domains).
  • Netcraft found an underground market selling access to more than 15,000 compromised .gov, .edu and ccTLD domains (Report 2 describes the 15,000+ figure as gov/edu domains only).
  • ADEX argues Google's site reputation abuse policy does not cover institutions hijacked without their knowledge, since hacked site owners are victims.

Coverage timeline

  1. · 1h ago
    Cyber Security News· 40
    Hacked Thai College Website Abused to Redirect Google Searchers to Illegal Online Casino

    ADEX uncovered a hacked Thai college domain serving casino pages through real Google search redirects, part of a global campaign compromising government and education sites.

  2. · 1h ago
    GBHackers· 45
    “Zero-Code Cloaking”: Attackers Weaponize Google Search and Hacked .ac.th Domain to Bypass Ad Moderation

    Attackers chain Google search results, a hacked Thai .ac.th domain, and redirects to push illegal casino ads past moderation, at industrialized scale across gov/edu sites.